Monday, July 15, 2019

Vuln: VideoLAN VLC CVE-2019-13602 Heap Based Buffer Overflow Vulnerability



VideoLAN VLC is prone to a heap-based buffer-overflow vulnerability.

Attackers can exploit this issue to cause a denial-of-service condition, denying service to legitimate users. Given the nature of this issue, attackers may also be able to execute arbitrary code, but this has not been confirmed.

VideoLAN VLC Media Player version 3.0.7.1 and prior are vulnerable.
exploit



Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.
solution



Solution:
Updates are available. Please see the references or vendor advisory for more information.

info



Bugtraq ID: 109158
Class: Boundary Condition Error
CVE: CVE-2019-13602
Remote: Yes
Local: No
Published: Jul 14 2019 12:00AM
Updated: Jul 14 2019 12:00AM
Credit: The vendor reported this issue.
Vulnerable: VideoLAN VLC media player 3.0.7
VideoLAN VLC media player 3.0.6
VideoLAN VLC media player 3.0.5
VideoLAN VLC media player 3.0.4
VideoLAN VLC media player 3.0.3
VideoLAN VLC media player 3.0.2
VideoLAN VLC media player 3.0.1
VideoLAN VLC media player 3.0
VideoLAN VLC media player 2.2.8
VideoLAN VLC media player 2.2.1
VideoLAN VLC media player 2.2
VideoLAN VLC media player 2.1.5
VideoLAN VLC media player 2.1
VideoLAN VLC media player 2.0.9
VideoLAN VLC media player 2.0.8
VideoLAN VLC media player 2.0.7
VideoLAN VLC media player 2.0.6
VideoLAN VLC media player 2.0.5
VideoLAN VLC media player 2.0.4
VideoLAN VLC media player 2.0.2
VideoLAN VLC media player 2.0.1
VideoLAN VLC media player 2.0
VideoLAN VLC media player 1.2
VideoLAN VLC media player 1.1.13
VideoLAN VLC media player 1.1.12
VideoLAN VLC media player 1.1.9
VideoLAN VLC media player 1.1.8
VideoLAN VLC media player 1.1.7
VideoLAN VLC media player 1.1.4
VideoLAN VLC media player 1.1.3
VideoLAN VLC media player 1.1.2
VideoLAN VLC media player 1.1.1
VideoLAN VLC media player 1.1
VideoLAN VLC media player 1.0.6
VideoLAN VLC media player 1.0.5
VideoLAN VLC media player 1.0.3
VideoLAN VLC media player 1.0.2
VideoLAN VLC media player 1.0.1
VideoLAN VLC media player 1.0
VideoLAN VLC media player 0.9.9
VideoLAN VLC media player 0.9.7
VideoLAN VLC media player 0.9.6
VideoLAN VLC media player 0.9.5
VideoLAN VLC media player 0.9.4
VideoLAN VLC media player 0.9.3
VideoLAN VLC media player 0.9.2
VideoLAN VLC media player 0.9.1
VideoLAN VLC media player 0.9
VideoLAN VLC media player 0.8.8
VideoLAN VLC media player 0.8.7
VideoLAN VLC media player 0.8.6
+ Debian Linux 4.0 sparc
+ Debian Linux 4.0 s/390
+ Debian Linux 4.0 powerpc
+ Debian Linux 4.0 mipsel
+ Debian Linux 4.0 mips
+ Debian Linux 4.0 m68k
+ Debian Linux 4.0 ia-64
+ Debian Linux 4.0 ia-32
+ Debian Linux 4.0 hppa
+ Debian Linux 4.0 arm
+ Debian Linux 4.0 amd64
+ Debian Linux 4.0 alpha
+ Debian Linux 4.0
VideoLAN VLC media player 0.6.8
VideoLAN VLC media player 0.5
VideoLAN VLC media player 0.1.13
VideoLAN VLC media player 3.0.7.1
VideoLAN VLC media player 2.2.5
VideoLAN VLC media player 2.2.4
VideoLAN VLC media player 2.2.3
VideoLAN VLC media player 2.2.2
VideoLAN VLC media player 2.1.6
VideoLAN VLC media player 2.1.3
VideoLAN VLC media player 2.1.2
VideoLAN VLC media player 2.1.1
VideoLAN VLC media player 2.0.3
VideoLAN VLC media player 1.1.6
VideoLAN VLC media player 1.1.5
VideoLAN VLC media player 1.1.11
VideoLAN VLC media player 1.1.10.1
VideoLAN VLC media player 1.1.10
VideoLAN VLC media player 1.0.4
VideoLAN VLC media player 0.7.1
VideoLAN VLC media player 0.2.50
Not Vulnerable:
references



References:


from SecurityFocus Vulnerabilities https://ift.tt/2lptxYh

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.